← Back to InsightsDigital Infrastructure

OT Governance Is Becoming a Building-Level Standard. Design It Before Vendors Connect.

Connected building platforms are pushing identity, access, segmentation, and data rights into the core operating standard. Owners who set that standard before the next vendor connects control the intelligence. Owners who wait inherit someone else's rules.

August 28, 2026 · By Drew Hall

OT Governance Is Becoming a Building-Level Standard. Design It Before Vendors Connect.

A building system used to be a closed loop. The HVAC controller talked to the HVAC equipment. The access control panel talked to the doors. The metering ran on its own wire. If a vendor wanted to touch it, they showed up on site, plugged in, and left. The attack surface was small because the connection surface was small.

That era is closing fast, and asset managers should understand what is replacing it before the next vendor contract gets signed.

Operational technology in commercial buildings is becoming connected, cloud-linked, and AI-enabled at a pace most owners have not budgeted for. Honeywell has publicly stated that its Forge platform is targeting 9 million connected assets by 2028, positioning the platform as the primary mechanism for delivering what the company calls physical AI to customers. That is one vendor, one platform, describing a future where millions of building systems are wired into a shared operating layer that can observe, analyze, and eventually act.

When that many systems become connected and start sharing data, identity, access, segmentation, source-system mapping, metadata, and data rights stop being an IT side project. They become a building-level requirement. The question for the owner is simple: whose standard governs all of it?

The Connection Surface Is Now the Risk Surface

Every system you connect to a shared platform is a new door into your building. That is true whether the door is a rooftop unit, a submeter, an elevator controller, or a lobby access panel. Each connection carries credentials, network reach, and a data flow. Multiply that across a portfolio and across a growing list of vendors, and the governance problem compounds faster than any single property team can track manually.

The financial world already lives with this reality. Apollo Global Management, an asset manager, disclosed a data breach after hackers targeted financial firms and stole personal information. The lesson for CRE is not that a breach is possible. Everyone knows that. The lesson is that when your operating data and your access pathways sit inside systems you do not fully govern, your exposure is defined by someone else's security posture, not your own.

In a building, the consequences are physical and financial at the same time. A compromised access control system is a life-safety event. A compromised building management system is an operating disruption. And a breach that touches tenant data or operating records becomes an insurance-claim exposure and a diligence finding, the kind of surprise asset managers are paid to prevent. When you connect more systems without a governing standard, you are not adding features. You are adding counterparty risk that does not show up on the P&L until something goes wrong.

AI Raises the Stakes Because AI Wants Permission to Act

The reason this matters more now than it did five years ago is that connected platforms are no longer just collecting data. They are being built to act on it.

The appetite is real. Recent research from MRI Software found that 82% of commercial real estate professionals believe AI is important to the industry's future success, yet 54% report that their organizations offer no AI training whatsoever. That gap between belief and readiness is where risk lives. Owners want the outcomes AI promises, but most have not built the governance that determines what an automated system is allowed to see, touch, and change.

Here is the mechanism that should concern any asset manager. An AI-enabled platform that can optimize energy can also reset setpoints, override schedules, and reconfigure equipment. That is the point of it. But automation without governance is just a faster way to make an unauthorized change. If the platform's permissions were set by the vendor to suit the vendor's product, then the vendor, not the owner, decides what the intelligence in your building is allowed to do.

This is where the reframing line earns its place. If you don't own your data & digital infrastructure, your vendors do. And when AI gets permission to act, whoever holds the permissions holds operational control of the asset.

Governance Only Scales If It Is a Repeatable Standard

The instinct at a single property is to solve this building by building. A network here, a firewall there, a vendor onboarding checklist somewhere in a shared drive. That approach fails at portfolio scale for a reason worth understanding.

When every property handles identity, segmentation, and data rights its own way, three things happen. First, you cannot compare buildings, because the underlying data is captured and structured differently at each address. Second, every new vendor connection requires custom work, which is slow and expensive and error-prone. Third, your operating history becomes fragmented and hard to trust, which weakens it exactly when you need it most, during refinancing and disposition, when a lender or buyer's diligence team asks for a clean, portable record of how the asset actually runs.

That portability point deserves weight, because it is where the governance question turns into a valuation question. When a lender underwrites a refinance, expense trajectory and operating history drive the terms. When a buyer's diligence team reviews an acquisition, gaps and inconsistencies in the operating record become negotiating ammunition against the seller. An owner who can hand over a clean, portable, standardized record of how every building runs holds a stronger position at the table. An owner whose data is trapped across a dozen vendor platforms, each formatted differently, arrives at diligence with a weaker hand and often a lower number. The governance standard you set today quietly shapes the price you get at exit.

The industry is beginning to name this problem out loud. Realcomm is running a webinar titled From Chaos to Clarity: Building a Trusted Foundation for CRE Technology, framing data quality as a defining factor in how CRE organizations manage risk, analyze portfolios, and prepare for what comes next. The framing is correct. Fragmented data is not a technical inconvenience. It is a governance failure that becomes a valuation problem.

What scales is not a stack of point solutions. What scales is a standard: one repeatable way to connect a building, capture its data, map source systems, attach metadata, and govern who and what is allowed to act, applied the same way at every address.

What a Building-Level Governance Standard Actually Contains

Abstract words like control and governance become empty unless you can point to what they mean operationally. For an owner, a real governance standard answers concrete questions before a vendor ever connects.

Can you segment the network so a compromised rooftop unit cannot reach the access control system? Can you map every source system so you know what data comes from where and whether it is trustworthy? Can you attach metadata so the data means the same thing across every building? Can you set permissions so an AI-enabled platform operates under your rules, not the vendor's defaults? And can you export your operating history and apply a different decision engine to it without losing years of data? If the answers live inside a vendor platform you cannot reach, you do not have a governance standard. You have a dependency.

This is the work OpticWise does through a two-layer model. Layer one is managed data & digital infrastructure: the owner-owned foundation delivered through our SIC® platform (Security, Infrastructure, Connectivity), with BoT® (Building of Things®) consolidating building connectivity onto a single, secure, segmented foundation. Layer two is the owner-controlled intelligence layer, Property Brain™ becoming Portfolio Brain™, a vendor- and LLM-agnostic governed data plane and trust plane. Vendors and their platforms plug in under owner permissions rather than dictating them.

The PPP 5C™ plan sequences the work so governance is designed in, not bolted on. Clarify through a PPP Review that maps ownership, identifies leakage, and documents what is trustworthy and portable. Connect through secure, owner-controlled connectivity built the same way property to property. Collect by normalizing high-fidelity data into a consistent model you can reuse. Coordinate by governing identity, access, privacy, lineage, retention, and rules of use. Control by enabling any decision engine, from any vendor and any LLM, to act only under owner permissions. This is how you set the standard before the vendors connect, not after.

Set the Standard Before the Next Vendor Connects

The timing pressure is straightforward. Connected assets are being added to portfolios right now, and every asset connected under a vendor's governance standard is harder to bring back under yours later. History, permissions, and integration all accrete in the vendor's favor with each passing quarter.

Asset managers already understand this pattern from other domains. You do not renegotiate a lease structure after the tenant has moved in. You do not fix a debt covenant after the loan closes. You set the terms before you sign. Data & digital infrastructure governance works the same way. Your negotiating position is strongest before the connection is made.

Start with one property. Run a PPP Review to establish your governance standard and map what you actually own today. Prove it works by connecting at least one system under your permissions. Then make it repeatable and scale it across the portfolio, so intelligence compounds on a foundation you control rather than restarting at every address.

Connected building platforms are not the enemy here. They are inevitable, and many of them are genuinely useful. The risk is connecting them under someone else's rules. The opportunity is connecting them under yours.

Own your data & digital infrastructure. Build for the long game.

Drew Hall

Drew Hall

Founder & Chief Architect, OpticWise • Co-Author, Peak Property Performance®

Drew Hall is the Founder and Chief Architect at OpticWise. He brings deep experience designing high-performance networks for demanding clients in both the commercial and federal sectors, including professional engagements with IBM and the US Department of the Interior. Drew's expertise is in extending advanced technologies to meet the unique needs of commercial real estate, and under his technical leadership, OpticWise has developed the SIC® engineering standard that powers owner-controlled data and digital infrastructure across properties. He holds a computer science degree from Baylor University and is the co-author of Peak Property Performance (Fast Company Press).

Your Next Step

Complimentary CRE Data & Digital Review Session

One building. Map who owns what, where data lives, who has permission to act on it, and where operational burden stacks up vs your KPIs.